I run the ZoneAlarm firewall on my DSL connection, and it will occaisonally report what it says are “attempts at security breaches” with my computers. Over the last few days, one series of IP’s have been trying many times to start a NetBios session on my PC. They are a list of about 20 or so on the 216.35.123.X domain.
My background - I have a decent understanding of TCP/IP and the coordination layers and how it works and it’s tools, but know little to nothing about NetBios, NetBUEI (sp), etc.
Three main questions:
-
What does it mean when another computer tries to start a NetBios session on mine? Does that mean it’s trying to use Windows shares?
-
Several sites recommend removing “NetBios over TCP/IP” in Windows 95, and give instructions on how to do that. Should I remove NetBios bindings to TCP/IP, or can this cause some net applications to stop working?
-
I ran a traceroute on one IP that was trying several times to start a NetBios session with me. So what was it trying to do? Below is the log. Any better way I can find out at least what ISP this computer is on?
Tracing route to 216.35.123.96 over a maximum of 30 hops
1 24 ms 32 ms 32 ms adsl-MYIPREMOVEDFORSECURITY.dsl.kscymo.swbell.net [MYIPREMOVEDFORSECURITY]
2 23 ms 24 ms 22 ms core1-fa1-1-0.kscymo.swbell.net [151.164.8.65]
3 21 ms 23 ms 23 ms edge1-fa0-1-0.kscymo.swbell.net [151.164.8.241]
4 21 ms 22 ms 23 ms mci1-core1-s1-0-0.atlas.digex.net [206.181.218.13]
5 31 ms 33 ms 30 ms okc1-core1-s0-0-0.atlas.digex.net [165.117.52.50]
6 38 ms 35 ms 37 ms dfw3-core1-s3-2.atlas.digex.net [165.117.56.5]
7 56 ms 56 ms 57 ms ord2-core4-pos5-0.atlas.digex.net [165.117.48.70]
8 58 ms 55 ms 56 ms ord2-core1-pos7-0.atlas.digex.net [165.117.48.89]
9 57 ms 57 ms 56 ms ord2-core2-pos7-0.atlas.digex.net [165.117.48.86]
10 55 ms 59 ms 58 ms ibr02-s2-7.okbr01.exodus.net [216.32.132.141]
11 98 ms 94 ms 96 ms bbr02-g2-0.okbr01.exodus.net [216.34.183.98]
12 97 ms 92 ms 93 ms bbr02-p0-0.sntc04.exodus.net [216.32.132.150]
13 93 ms 95 ms 91 ms dcr01-g6-0.sntc04.exodus.net [216.34.2.1]
14 96 ms 97 ms 94 ms rsm06-vlan921.sntc04.exodus.net [216.34.2.92]
15 95 ms 94 ms 91 ms 216.35.123.45
16 94 ms 92 ms 90 ms 216.35.123.96
Trace complete.
Thanks all!